peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6334 EXP Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 7.8 high 2.8% 2009-02-27
CVE-2008-6335 EXP Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to read arbitrary files via a .. (do… Patch early 7.8 high 2.8% 2009-02-27
CVE-2004-2368 EXP PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath paramete… Patch early 7.5 high 2.8% 2004-12-31
CVE-2005-0678 EXP PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.8% 2005-05-02
CVE-2005-1375 EXP Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbi… Patch early 7.5 high 2.8% 2005-05-03
CVE-2007-4978 EXP Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 7.5 high 2.8% 2007-09-19
CVE-2007-5313 EXP PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2.8% 2007-10-09
CVE-2007-6655 EXP PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a U… Patch early 7.5 high 2.8% 2008-01-04
CVE-2009-4645 EXP Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to… Patch early 7.8 high 2.8% 2010-02-19
CVE-2018-10619 EXP An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an a… Patch early 7.8 high 2.8% 2018-06-07
CVE-2006-4764 EXP PHP remote file inclusion vulnerability in common.php in Thomas LETE WTools 0.0.1-ALPH allows remote attackers to execute arbitrary PHP code via a URL… Patch early 7.5 high 2.8% 2006-09-13
CVE-2006-4970 EXP PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to execute arbitrary PHP code via a… Patch early 7.5 high 2.8% 2006-09-25
CVE-2006-5062 EXP PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbi… Patch early 7.5 high 2.8% 2006-09-28
CVE-2006-5226 EXP PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP… Patch early 7.5 high 2.8% 2006-10-10
CVE-2006-5261 EXP Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.8% 2006-10-12
CVE-2006-5426 EXP PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbitrary PHP code via a URL in the… Patch early 7.5 high 2.8% 2006-10-20
CVE-2006-5588 EXP Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and magic_quotes_gpc are enabled, al… Patch early 7.5 high 2.8% 2006-10-27
CVE-2002-0732 EXP Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user n… Patch early 7.5 high 2.8% 2002-08-12
CVE-2006-0522 EXP SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote… Patch early 7.5 high 2.8% 2006-02-02
CVE-2013-7185 EXP PotPlayer 1.5.40688: .avi File Memory Corruption Patch early 7.8 high 2.8% 2020-01-14
CVE-2005-3639 EXP PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files… Patch early 7.5 high 2.8% 2005-11-16
CVE-2023-33137 EXP Microsoft Excel Remote Code Execution Vulnerability Patch early 7.8 high 2.7% 2023-06-14
CVE-1999-0149 EXP The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack. Patch early 7.5 high 2.7% 1997-04-19
CVE-2000-0412 EXP The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files… Patch early 7.5 high 2.7% 1999-05-01
CVE-2006-5787 EXP admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, poss… Patch early 7.5 high 2.7% 2006-11-07
CVE-2017-5264 EXP Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web appl… Patch early 8.8 high 2.7% 2017-12-14
CVE-2006-6569 EXP form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2)… Patch early 7.8 high 2.7% 2006-12-15
CVE-2019-14346 EXP Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. Patch early 8.8 high 2.7% 2019-08-06
CVE-2008-2293 EXP admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentS… Patch early 7.5 high 2.7% 2008-05-18
CVE-2009-0078 EXP The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 200… Patch early 7.2 high 2.7% 2009-04-15
← previous page 251 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt